No items found.
Event

SANS Institute Cyber Solutions Fest

Date
March 18, 2025
Time
8:30 AM - 1:00 PM ET
Event Type
Virtual
Location
North America

Explore the hidden risks of open-source software at the Cyber Solutions Fest: Spring. While open source has revolutionized modern application development, its reliance on volunteer-driven code introduces significant security vulnerabilities. This session will dive into how supply chain attacks, like the CodeCov incident and malicious packages on npm and PyPi, are exploiting these weaknesses. Attendees will gain insights into how to integrate open-source supply chain security into their threat modeling processes, ensuring safer development practices. Learn about attack vectors, practical defenses, and strategies to bolster your security posture from day one of development.

Join us to understand the evolving landscape of open-source risks and how to mitigate them effectively.

GHSA-864f-rcv7-6rh4: Critical Type Confusion Vulnerability in isolated-vm
GHSA-864f-rcv7-6rh4: Critical Type Confusion Vulnerability in isolated-vm
Read more
CISO's Guide: Build vs Buy AI Code Security
CISO's Guide: Build vs Buy AI Code Security
Read more
NPM Malware Compromises keyv and cacheable with 500M+ Weekly Downloads and Spreads to Hundreds of Packages
Read more
GHSA-864f-rcv7-6rh4: Critical Type Confusion Vulnerability in isolated-vm
GHSA-864f-rcv7-6rh4: Critical Type Confusion Vulnerability in isolated-vm
Read more
CISO's Guide: Build vs Buy AI Code Security
CISO's Guide: Build vs Buy AI Code Security
Read more
NPM Malware Compromises keyv and cacheable with 500M+ Weekly Downloads and Spreads to Hundreds of Packages
Read more

Want to stay in the loop?

Sign up for our newsletter.